CVE-2011-4859 - CVE House
Back to Database
Status published Critical CVE-2011-4859

The Schneider Electric Quantum Ethernet Module, as used in the...

Vulnerability Description

The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded passwords for the (1) AUTCSE, (2) AUT_CSE, (3) fdrusers, (4) ftpuser, (5) loader, (6) nic2212, (7) nimrohs2212, (8) nip2212, (9) noe77111_v500, (10) ntpupdate, (11) pcfactory, (12) sysdiag, (13) target, (14) test, (15) USER, and (16) webserver accounts, which makes it easier for remote attackers to obtain access via the (a) TELNET, (b) Windriver Debug, or (c) FTP port.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-4859

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

schneider-electric

View all reports →

Affected Software

quantum ethernet module 140cpu65150, quantum ethernet module 140cpu65160, quantum ethernet module 140cpu65260, quantum ethernet module 140noe77100, quantum ethernet module 140noe77101, quantum ethernet module 140noe77111, premium ethernet module tsxety4103, premium ethernet module tsxety5103, premium ethernet module tsxp57163m, premium ethernet module tsxp572634m, premium ethernet module tsxp573634m, premium ethernet module tsxp574634m, premium ethernet module tsxp575634m, premium ethernet module tsxp576634m, m340 ethernet module bmxnoe0100, m340 ethernet module bmxnoe0110, m340 ethernet module bmxp342020, m340 ethernet module bmxp342030, stb dio ethernet module stbnic2212, stb dio ethernet module stbnip2212, stb dio ethernet module stbnip2311
Vulnerable Versions:
0

Timeline

Official Publish: December 17th, 2011
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.